
Jovvie In Person Payments for Event Tickets Security & Risk Analysis
wordpress.org/plugins/tec-jovvie-payments-gatewayAccept in person card payments for events using Event Tickets within the The Events Calendar ecosystem.
Is Jovvie In Person Payments for Event Tickets Safe to Use in 2026?
Generally Safe
Score 100/100Jovvie In Person Payments for Event Tickets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "tec-jovvie-payments-gateway" v1.0.2 reveals a generally strong security posture with no identified critical or high-severity vulnerabilities in the provided data. The plugin demonstrates good practices by employing prepared statements for all SQL queries and implementing nonce and capability checks. The attack surface is minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points were detected. The absence of external HTTP requests further reduces the risk of remote code execution or data exfiltration through such channels.
However, a notable concern lies in the output escaping. While a significant portion of outputs are properly escaped, 265 total outputs with only 74% properly escaped indicates that a substantial number of outputs (approximately 69) are not adequately sanitized. This presents a potential Cross-Site Scripting (XSS) risk if untrusted user input is directly reflected in these unescaped outputs. The taint analysis showing zero flows is positive, but the existence of unescaped output means that potential XSS vulnerabilities might not have been flagged by this specific analysis if user input isn't directly linked to those outputs in the analyzed code paths.
The plugin's vulnerability history is entirely clean, with zero known CVEs recorded. This is a very positive indicator, suggesting a well-maintained and secure plugin thus far. However, this clean history, combined with the identified output escaping weakness, suggests that the plugin might not have been extensively targeted or rigorously tested for all types of vulnerabilities, particularly XSS. In conclusion, while the plugin exhibits strong foundational security practices and a clean history, the significant percentage of unescaped outputs is a tangible risk that warrants attention and remediation to prevent potential XSS attacks.
Key Concerns
- Significant percentage of unescaped output
Jovvie In Person Payments for Event Tickets Security Vulnerabilities
Jovvie In Person Payments for Event Tickets Code Analysis
Output Escaping
Jovvie In Person Payments for Event Tickets Attack Surface
WordPress Hooks 6
Maintenance & Trust
Jovvie In Person Payments for Event Tickets Maintenance & Trust
Maintenance Signals
Community Trust
Jovvie In Person Payments for Event Tickets Alternatives
Jovvie Point of Sale POS for WooCommerce
point-of-sale-pos-woocommerce
The Ultimate WooCommerce Point of Sale Solution to Sell Anywhere.
Easy Custom Event Tickets
custom-event-tickets
Dupliquez vos événements et affichez la liste des participants pour The Events Calendar et Event Tickets.
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Jovvie In Person Payments for Event Tickets Developer Profile
7 plugins · 3K total installs
How We Detect Jovvie In Person Payments for Event Tickets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tec-jovvie-payments-gateway/dist/checkout.css/wp-content/plugins/tec-jovvie-payments-gateway/dist/checkout.js/wp-content/plugins/tec-jovvie-payments-gateway/dist/checkout.jstec-jovvie-payments-gateway/dist/checkout.css?ver=tec-jovvie-payments-gateway/dist/checkout.js?ver=HTML / DOM Fingerprints
TEC_JOVVIE_PAYMENTS_GATEWAY_CHECKOUT_AJAX_URLTEC_JOVVIE_PAYMENTS_GATEWAY_CHECKOUT_AJAX_PROCESS_PAYMENTTEC_JOVVIE_PAYMENTS_GATEWAY_CHECKOUT_NONCE/wp-json/tec_jovvie_payments_gateway/v1/webhook